IP purity scoring
One 0–100 score, higher is better. This page describes the current scoring model 2.3; any rule change bumps the version, and result pages show which version was used.
Two ground rules
- No data is not clean. Missing evidence only lowers confidence; it never raises the score.
- Not enough evidence, no score. We never normalize the remaining dimensions into an inflated number.
Five dimensions and weights
| Dimension | Weight | What it looks at |
|---|---|---|
| Reputation | 32% | Blocklists, threat intelligence, mail reputation |
| Abuse history | 27% | Fraud and abuse reports |
| Anonymization | 23% | VPN, proxy, Tor or datacenter exit |
| Geo agreement | 10% | Whether geolocation databases agree (agreement, not accuracy) |
| Port exposure | 8% | Open proxy, remote-admin or database ports |
When a score is given
All of the following must hold; otherwise the page says "not scored" and explains why:
- the reputation dimension has an answer;
- weighted coverage is at least 60%;
- at least two of the three security dimensions (reputation, abuse, anonymization) have an answer.
Opening the home page runs a basic check that does not send your IP to third-party intelligence sources, so it may not produce a score; "run deep check" fills in the rest.
Caps
These cap the score. If several apply, the lowest wins and all are listed:
| Condition | Maximum |
|---|---|
| Hard threat-intel hit (criminal-controlled ranges, active C2, …) | 19 |
| Tor exit | 0 |
| Residential proxy | 54 |
| VPN | 54 |
| Datacenter network (network-type confidence ≥ 0.5) | 54 |
Model 2.3 sets Tor exits to 0: their purpose is to hide the origin, so a detected Tor exit scores 0 and lands in "Severe". Model 2.2 lowered the datacenter and VPN cap from 69 to 54, the same band as residential proxies, because most platforms scrutinize datacenter exits noticeably harder. It does not mean these addresses are malicious. IP type (residential, datacenter, …) only acts through the cap and is never deducted again in a dimension: one fact is used once.
Hard intelligence and soft signals
- Hard intelligence takes the worst hit. Definitive claims (a range controlled by criminals, active C2) use the most severe hit and trigger the cap.
- Soft signals accumulate. Reports, DNSBLs and fraud scores combine as noisy-OR:
risk = 1 − Π(1 − rᵢ × confidenceᵢ × recencyᵢ). No single weak signal can veto on its own. - Recency decay. 1.0 within 30 days, 0.6 within 180 days, 0.3 beyond; unknown dates count as 0.6, not as fresh.
- De-duplication. The unit of scoring is the evidence family, not the data source: an aggregator cannot vote again alongside its upstream; only one hit per family counts, and cross-family repeats are weighted by 0.4.
Port exposure
Only the worst category counts: proxy ports (1080, 3128, 8080, …) −40, remote admin (23, 3389, 5900) −25, databases (3306, 5432, 6379, …) −15, other ports −10; each extra category adds 5, capped at 60 in total. CVEs are not scored, since that would systematically penalize people who self-host.
Grade bands
| Score | Grade |
|---|---|
| 85–100 | Clean |
| 70–84 | Fairly clean |
| 55–69 | Check |
| 40–54 | Elevated risk |
| 20–39 | High risk |
| 0–19 | Severe |
What is not scored
WebRTC leaks, DNS leaks, identity consistency and dual-stack exits can only be tested by the IP's holder and describe device setup rather than the IP, so they are shown as optional tests outside the score. Routing, registry details and some shadow sources are shown for information only.
Where the data comes from: sources.